[00:00.000 --> 00:09.320] Two years ago at the last HOPE conference, we basically went over the Zeus and the spy Trojans as well as a few exploit kits. [00:09.960 --> 00:13.780] And back then, the things were a bit different. [00:13.900 --> 00:15.560] A lot has changed in 24 months. [00:16.860 --> 00:20.560] A bit about me for those who are... this is their first time. [00:20.900 --> 00:23.020] I worked in information security. [00:23.500 --> 00:29.140] I've worked with defense contractors and banks doing vulnerability analysis and penetration testing. [00:29.140 --> 00:38.800] I'm currently working with the PLX cert team at Prolexic doing forensics, intelligence analysis, and threat research on DDoS tools and techniques. [00:39.100 --> 00:45.020] And I'm also president of Hack Miami hackerspace out of South Florida and on the board of the South Florida OWASP. [00:47.060 --> 00:53.000] And standard disclaimer, all the information contained in this presentation is for informational purposes only. [00:53.540 --> 00:55.320] Don't actually attack servers. [00:55.320 --> 00:56.540] We're going to discuss vulnerabilities. [00:57.380 --> 01:00.320] Don't actually engage live systems. [01:00.860 --> 01:08.660] We've... Downstairs in the mezzanine level, we have capture the flag that's running that incorporates all the tools that we're going to be discussing in this. [01:08.760 --> 01:14.160] So, if you want to... if you're looking to exploit some crime kits, we have a very safe lab environment downstairs to be able to do that with. [01:14.320 --> 01:17.380] And you'll be able to try out the exploits that we'll be going over. [01:18.080 --> 01:26.020] And, you know, even if you do really want to try it and you find, you know, bulletproof servers that are hosting this type of stuff, don't do it if you're an American. [01:26.360 --> 01:27.940] The FBI likes to hunt Americans. [01:27.940 --> 01:37.120] And all information that's contained in this was obtained legally through third parties in accordance to the laws of the land from which they reside. [01:39.560 --> 01:43.640] So, the last time we spoke, Zeus 2.0 was still a private kit. [01:43.880 --> 01:48.460] The older versions of Zeus were circulating publicly, but the 2.0 was still private. [01:49.220 --> 01:52.440] SpyEye was fairly new and hadn't yet been publicly leaked. [01:53.240 --> 01:57.860] Automated credit card shops, those were a rare phenomenon. [01:58.420 --> 02:04.120] They had started to emerge, but they weren't as prevalent as they are today. [02:05.000 --> 02:09.940] Most of the crimeware kits, the vulnerabilities that existed, were still private. [02:10.140 --> 02:17.820] They were just circulated among the underground and within the intelligence communities, but they weren't disclosed in public knowledge like they are today. [02:18.400 --> 02:21.480] The black hole exploit kit was in its infancy. [02:21.680 --> 02:25.660] Today, it's one of the primary exploit kits that are in use. [02:26.860 --> 02:28.720] Things like Bitcoin didn't exist. [02:29.120 --> 02:34.320] Peer-to-peer cryptocurrency as a concept has emerged within the last two years. [02:34.480 --> 02:38.400] And Adobe products in 2010 were the most vulnerable vector. [02:38.640 --> 02:40.380] That is also now changed. [02:42.640 --> 02:44.940] And here, you know, just a bit of nostalgia. [02:44.940 --> 02:55.540] Here's where the black hole beta kit back from 2010 before it was publicly on the market or before it was the comprehensive product that is today with licensing and automatic updates and all that stuff. [02:55.760 --> 03:02.200] That was back when Phoenix and Fragus and Yes were still the main exploit kits that were circulating the underground. [03:04.260 --> 03:09.620] And since this time, Java is now the new attack vector of choice. [03:10.080 --> 03:13.460] Oracle seems to be slow to patch their updates. [03:14.040 --> 03:27.500] Automated fraud shops are now so common that just Googling CVV shop will lead you dozens of results and dozens of news articles about recent FBI arrests and raids and domain seizures related to that market. [03:27.500 --> 03:32.000] The major crime work kits such as Zeus and SpyEye are now public. [03:32.540 --> 03:37.060] Down to the source code level where you can even examine the code of the builders that are making the executables. [03:37.720 --> 03:40.120] And vulnerabilities in crime work kits have been made public. [03:40.280 --> 03:45.920] Remote file inclusions, file uploads in Zeus and SQL injections in SpyEye and Eleanor as well as others. [03:48.640 --> 03:51.160] Also, DDoS attacks have become more prevalent. [03:51.700 --> 04:07.020] The rise of hacktivism over the last two years with the whole, all the different anonymous campaigns, that really significantly increased the focus of media attention on DDoS attacks and the overall awareness of DDoS attacks. [04:07.020 --> 04:13.980] And the more tools are now available to conduct these types of attacks that are simpler than ever. [04:14.440 --> 04:15.680] Specifically, booter scripts. [04:16.020 --> 04:25.500] The bar has been lowered when it comes to the technological requirements, the understanding to be able to launch these attacks. [04:26.220 --> 04:38.740] The concept of opt-in botnets also emerged, where instead of spreading malware among different machines, you will just convince users to run a tool and participate in a target. [04:38.980 --> 04:42.460] So you're basically becoming part of a botnet because you're choosing to. [04:42.620 --> 04:46.920] It's part of the hacktivist techniques or digital activism. [04:47.600 --> 04:55.060] New crime work kits were released, specifically Dirt Jumper, which is a Russian DDoS toolkit. [04:55.420 --> 04:56.820] Actually very potent. [04:58.200 --> 05:00.100] We'll be going into it in detail later. [05:00.100 --> 05:08.080] And also Zemra was another Trojan, which has recently been released into the news and leaked and also discussed in the news. [05:08.160 --> 05:10.160] And we'll be going into that into detail as well. [05:11.160 --> 05:15.100] Again, there's been an increase in law enforcement activity surrounding all of this. [05:15.300 --> 05:20.120] And there's been an emergence of peer-to-peer cryptocurrencies like Bitcoin. [05:20.120 --> 05:23.020] But there's been a surprising lack of interest from the underground. [05:23.020 --> 05:26.800] It hasn't really... it hasn't really completely taken off. [05:27.020 --> 05:30.960] And that's probably a good thing because a lot of good things can be done with Bitcoin. [05:33.920 --> 05:35.760] The new attack vector of Java. [05:36.260 --> 05:45.100] Most new exploit kits, specifically the black hole exploit kit, they now make use of Java vulnerabilities, which are have... which are released. [05:45.380 --> 05:47.500] And Oracle is very, very slow to patch. [05:47.500 --> 05:51.580] They have a pretty slow patching cycle. [05:51.760 --> 05:57.980] So it could be several weeks to several months from the time of vulnerabilities disclosed to the time Oracle gets around to actually patching it. [05:58.200 --> 06:02.600] So that window of opportunity is very large. [06:02.840 --> 06:11.660] And attackers are leveraging that window of opportunity and developing exploits that are Java-based and including them into automated exploit kits for things like drive-by downloads. [06:11.660 --> 06:20.560] The new version of black hole advertises the... advertises Java vulnerability as reported on Krebsonsecurity.com. [06:23.740 --> 06:27.780] And automated... we also have the rise of the automated fraud shop. [06:28.060 --> 06:48.400] These are basic PHP MySQL scripts that are... that sell digital goods, except in this case the digital goods are usually credit card numbers, mag stripe data, PayPal logins, email accounts, or basically any other type of collected credential that can be used for some type of fraudulent activity. [06:48.920 --> 06:55.840] The way these work is users will either pay a fee to join the site and they've usually heard about it from a carding form or something like that. [06:56.300 --> 07:01.240] And they'll usually have to pay a fee to even register to be able to access the site. [07:01.340 --> 07:09.920] And then once they've paid that fee, they can fund their account and then just start adding items to their shopping cart and check out with an anonymous e-currency. [07:10.500 --> 07:15.320] And usually you can get away with several... [07:15.320 --> 07:17.100] a good amount of credit card numbers for... [07:17.100 --> 07:25.500] depending on the shop, between two to five dollars a piece or seven to... or ten dollars above a piece for European cards. [07:26.100 --> 07:32.620] And the scripts originally were exclusively private scripts that were... [07:32.620 --> 07:36.500] you had to either buy it... you had to buy it from a developer on a carding form. [07:36.960 --> 07:41.500] But as time goes on, customers get disgruntled and scripts get leaked. [07:42.420 --> 07:45.380] So now these types of scripts are freely available. [07:45.680 --> 07:48.860] If you look around on forums, people are giving them away. [07:49.000 --> 07:51.720] People are... there have been hacked ones that have been released. [07:52.260 --> 07:58.640] And several of the most popular shops have been breached by pretty much everyone in the book. [07:58.640 --> 08:02.360] everyone's been hitting these sites because they're... [08:02.360 --> 08:11.960] they're a trove of both, you know, pirate digital booty and intelligence for both the security consultants and law enforcement. [08:12.820 --> 08:24.200] Most recent raid was Operation Card Shop, which took place in June of this year where the FBI did a sweep and arrested 24 people who were engaged in carding activity. [08:24.200 --> 08:26.200] Some people were also running automated shops. [08:26.420 --> 08:32.680] And they also had created a honeypot forum called Carter's Profit that was run by the FBI. [08:32.960 --> 08:38.640] And basically they just kind of sat back and watched as Carter's from all over came and started engaging in transactions. [08:38.920 --> 08:42.420] And then they closed up shop in June and made 24 arrests. [08:45.240 --> 08:49.060] One notable breach took place during the spring of 2011. [08:49.060 --> 08:54.180] A French... it was reported on a French language information security blog. [08:54.720 --> 08:59.060] Apparently a French hacker was able to breach a credit card selling shop. [08:59.400 --> 09:05.100] And once they breached it, they were able to obtain the actual PHP scripts for the shop and the MySQL database. [09:05.440 --> 09:14.680] And with that they were able to get administrative access to the application, a list of all the users on the shop, all their passwords, all the transaction data as well. [09:17.720 --> 09:23.260] Word of the breach spread pretty quickly because it was a pretty prominent site. [09:23.900 --> 09:27.880] It was on... it was discussed on Pacebit and various other underground forums. [09:28.380 --> 09:37.740] When this was going on, some of our researchers at HackMiami were able to obtain screenshots that were being posted on the forums by the person who had done the breaches. [09:37.740 --> 09:46.620] And they were able to... basically they were able to see the statistics from the administrative panel. [09:46.800 --> 09:52.520] Which gave... which gives a good snapshot as to the scale of the underground economy that's going on. [09:52.560 --> 09:55.940] Especially when this is just... we take into account that this is just a single website. [09:56.200 --> 09:57.540] And there are hundreds of them now. [09:58.060 --> 10:00.360] And so let's look at... let's look at some statistics. [10:03.800 --> 10:08.840] This is the... this is the statistics panel from the card shop, from the administrator panel. [10:09.040 --> 10:12.260] You know, they can log in and manage their sales and see exactly what they're doing. [10:13.460 --> 10:23.000] From between April 2010 and April 2012, there were... there was over $600,000 worth of data that was sold on the... [10:23.000 --> 10:26.520] on the site through... through Liberty Reserve e-currency. [10:26.920 --> 10:32.320] There... it looks like their... their largest... their most busy month was... [10:33.460 --> 10:36.060] was August and September of 2010. [10:36.260 --> 10:37.420] That's when they... they peaked. [10:37.540 --> 10:44.500] They made about... about a hundred... close to $200,000 just in those two months. [10:44.500 --> 10:49.360] And the... the rest of... and then the rest of the month just kind of... kind of trickled off as... [10:49.360 --> 10:51.780] as... I guess as they got into... to other things. [10:53.020 --> 10:57.280] Most... most of the time... the people running these shops aren't hackers themselves. [10:57.580 --> 11:04.780] They're simply... buying up bulk databases from hackers and then including it as inventory in their shop and marking up the price. [11:07.700 --> 11:11.180] Here's another statistical analysis from... from the shop. [11:11.180 --> 11:14.220] This was the top users, the top 10 purchasers. [11:14.720 --> 11:20.540] About 9% of the business from... for the entire shop came from the top... came from the top 10 users. [11:21.080 --> 11:25.440] And over the course of the year, just those 10 users spent about $55,000... [11:26.400 --> 11:29.080] on this... buying credit cards from this site. [11:32.010 --> 11:36.830] And the administrator is obviously sloppy, which is why we're able to be looking at these statistics today. [11:37.410 --> 11:42.250] They were able to... for some reason, they appeared to have a backup file called... [11:42.250 --> 11:47.790] test.txt that had every single Liberty Reserve transaction that had ever taken place on the website. [11:48.090 --> 11:51.690] Destination account numbers... where the account number... where the... [11:51.690 --> 11:53.270] funds were coming from. [11:53.450 --> 11:55.670] The... the batch ID of the transaction. [11:55.950 --> 11:57.230] And the amount that it was for. [11:57.610 --> 12:02.450] So... basically... any... anyone who ever bought a credit card number from this site... [12:02.450 --> 12:06.830] their... their... their account information was available for public viewing... [12:06.830 --> 12:09.790] just by browsing to test.txt on this shop. [12:13.900 --> 12:18.900] And... in addition to leaks such as that... we've had things like Zeus and SpyEye... [12:19.480 --> 12:25.880] that have... that have... been leaked through... various... public... publicly accessible malware forms. [12:27.520 --> 12:34.580] The... the... the... the... there's been a significant increase... in... in... in... in... infections... in... the... [12:34.580 --> 12:38.060] participation in these communities overall because these... [12:38.800 --> 12:41.940] previously... private kits are now publicly available for free. [12:42.100 --> 12:44.340] Whereas they used to cost a few hundred to a few thousand dollars. [12:44.600 --> 12:46.520] You can just download them and play with them. [12:46.520 --> 12:52.600] And... um... again... most of the public releases... uh... contain... back doors. [12:52.900 --> 12:57.780] Because they're releasing them... with the intention of being able to take over... uh... botnets... [12:57.780 --> 13:00.440] once people have start using the tools and... and making it work. [13:01.320 --> 13:04.700] And... um... also... because these are now publicly available... [13:04.700 --> 13:10.240] you have an entire community dedicated to... researching... uh... the scripts... and... uh... quote... [13:10.240 --> 13:12.680] looking for vulnerabilities within the command and control servers. [13:12.680 --> 13:16.620] And there's been... many... that have been discovered... and publicly released. [13:16.800 --> 13:18.120] And we'll be going over several of those. [13:20.480 --> 13:21.700] Here are some Zeus vulnerabilities. [13:22.240 --> 13:24.680] And... and again... all these vulnerabilities we're gonna be discussing... [13:25.360 --> 13:26.920] um... try them in a lab environment. [13:27.140 --> 13:28.920] We've got one downstairs on the mezzanine level. [13:29.120 --> 13:30.220] All these kits are set up. [13:30.300 --> 13:31.900] You can run these exploits against them... [13:31.900 --> 13:32.580] and see how they work. [13:33.680 --> 13:36.240] Um... Zeus... has a remote file upload vulnerability. [13:36.840 --> 13:41.720] Uh... previously this was... uh... just... uh... circulated among very small... uh... communities of people. [13:41.720 --> 13:44.080] Um... mostly within the security industry. [13:44.360 --> 13:45.780] And... uh... also within the underground. [13:47.040 --> 13:48.740] Um... basically... when Zeus communicates... [13:49.400 --> 13:50.820] to the command and control server... [13:50.820 --> 13:52.460] it sends an encrypted post request. [13:52.700 --> 13:54.180] And that encrypted post request... [13:54.180 --> 13:56.000] will write a file to the server... [13:56.000 --> 13:57.900] that has all their key log data... [13:57.900 --> 14:00.360] and the stuff that the Trojan's been collecting from the machine. [14:00.980 --> 14:03.840] And by... impersonating a bot... [14:03.840 --> 14:07.400] and sending a post request... that's encrypted with the key from the server... [14:07.400 --> 14:10.660] which can... and you can either... uh... you can obtain the key... [14:10.660 --> 14:16.340] For Zeus, the encryption key, either by extracting it from one of the binaries or just with a simple brute force attack. [14:16.900 --> 14:28.100] If you encrypt a post request, sending it to the gate.php drop zone for Zeus, it's possible to write PHP files and executable files to the server. [14:28.600 --> 14:40.540] And if you can browse directly to the reports directory and find where that file is, you'll be able to execute it and you'll get like a C99 or an R57 or whatever you've uploaded to the server to execute just by accessing it. [14:41.420 --> 14:58.420] If you, analysts, it's very possible if you browse through the reports directories on various public Zeus botnets, if they're publicly accessible, there's a good chance you're going to find C99 and R57 shells that are already there. [14:58.780 --> 15:05.800] And you can just kind of see the compromised bot as is. [15:05.800 --> 15:16.580] Back in the fall of 2010, a security researcher named Billy Rios from XS-Sniper.org put out a very cool tool. [15:16.580 --> 15:24.220] It's a PHP script that will emulate the post request to upload a file to a Zeus botnet. [15:24.220 --> 15:35.640] So you can, if you know the encryption key, you can just pop it into the script or you can set it to a little tweaking on it, make it brute force the script or just set and try to extract it from the binary. [15:35.640 --> 15:52.800] And we also, and in addition, and regarding extracting the key from the binary, there's a blog on ThreatExpert called Almighty Zeus that describes the process of extracting the encryption key from a Zeus binary. [15:52.800 --> 15:59.960] So that combined with Billy Rios' tool can result in compromising with his botnets. [16:00.080 --> 16:01.540] And again, don't do this in the wild. [16:02.320 --> 16:03.500] It's attacking a server. [16:03.900 --> 16:05.760] You can do it downstairs and you won't go to jail. [16:05.900 --> 16:06.800] And it's much more fun. [16:10.100 --> 16:16.340] SpyEye had multiple SQL injection vulnerabilities that have been, that have recently been public, made public. [16:16.940 --> 16:22.740] There are blind SQL injections on those two files, Form Finder App Sub 2 and Form Cards Edit. [16:23.320 --> 16:30.160] The ID parameters are unsanitized and vulnerable to SQL injection. [16:30.160 --> 16:35.560] There's been a blog that was also written by Seknichi. [16:35.920 --> 16:46.640] And they were, they go step by step on extracting database information from the SpyEye database through the SQL, through an SQL injection attack. [16:47.360 --> 16:51.600] There's two vectors of attack that you can use with an SQL injection against SpyEye. [16:51.780 --> 16:58.520] You can either use the SQL injection to read configuration files on the server and pull, pull credentials that way. [16:58.520 --> 17:01.120] Or you can use it to read the database and pull credentials that way. [17:01.220 --> 17:05.120] It depends on how the SpyEye administrator has set it up. [17:05.640 --> 17:07.010] But again, only do it in a lab. [17:09.660 --> 17:13.460] Other crime work kits have also had public vulnerabilities. [17:13.680 --> 17:19.240] The Eleanor exploit kit, which we discussed about two years ago is one of the more popular exploit kits in 2010. [17:19.660 --> 17:22.620] It now has public SQL injection vulnerabilities. [17:22.620 --> 17:29.940] A PDF was released on ExploitDB called Hacking the Skitties, which is about taking over Eleanor exploit kits. [17:30.480 --> 17:37.200] And the Black Energy DDoS botnet also has an SQL injection vulnerability that allows you to dump entries from the database. [17:37.380 --> 17:44.640] And that was also released by Billy Rios, the same researcher who released the Zeus backdoor. [17:44.640 --> 17:48.480] And again, only do white hat vigilante stuff in a lab. [17:50.660 --> 17:55.880] And there's been a resurgence of DDoS. [17:56.020 --> 18:01.420] Distributed denial of service has become more prevalent within the last two years. [18:01.580 --> 18:10.900] Mostly due to the rise of hacktivism causes and various global movements that are using DDoS as a protest tool. [18:10.900 --> 18:27.940] The use of traditional malware-based botnets that conducted DDoS, things like Dirtjumper, or those old-school IRC botnets that do DDoS attacks, those merge with the concept of opt-in botnets. [18:27.940 --> 18:46.600] And those are tools that we'll be going into like the high orbit ion cannon and the low orbit ion cannon, which specifically are one single user denial of service tools that become distributed that denial of service when enough participants gather for the attack. [18:46.920 --> 18:57.080] And as we stated earlier, the bar for the technical barrier of entry has significantly been lowered for attackers wishing to participate in DDoS attacks. [18:57.080 --> 19:02.600] because the toolkits and scripts that are available now are incredibly simple to use and very potent. [19:06.370 --> 19:14.030] Dirtjumper is a powerful botnet toolkit that was released publicly at the end of 2011. [19:14.330 --> 19:18.810] It was available in private since about January of 2011 for sale. [19:18.810 --> 19:22.030] It was selling for about 600 bucks, and then it got leaked around October. [19:22.590 --> 19:26.610] It was made as a spinoff from the Rooskill strain of malware. [19:26.850 --> 19:28.150] It's definitely a Russian botnet. [19:28.190 --> 19:29.550] It's very stripped down and simple. [19:31.890 --> 19:40.370] It's primary... the way... most of the way people get infected with it is they won't just get hit with a drive-by download, and then already... and then it'll just get hit with Dirtjumper. [19:40.510 --> 19:51.590] They'll usually already be infected with some kind of malware, and Dirtjumper will just be a payload that's pushed out to it later on, when they want to be able to... when they want to be able to utilize DDoS attack from their already existing botnet. [19:53.210 --> 19:56.790] The CNC panel of Dirtjumper is actually fairly secure. [19:56.970 --> 20:01.050] You can't even access the login page unless you know the username and send it in a get request. [20:01.230 --> 20:03.550] And it's got fake 404 errors all over it. [20:03.610 --> 20:12.410] So if you're trying to fingerprint it with a fuzzing... with a web fuzzing application like WFuzz, it's going to give you a seemingly legitimate 404 responses. [20:12.410 --> 20:18.910] But there are subtle differences between the real 404 responses and the Dirtjumper generated 404 responses. [20:19.170 --> 20:24.150] So you can kind of get a feel for if there is an actual command and control server there. [20:24.870 --> 20:27.490] It advertises that it makes use of four different attack methods. [20:28.030 --> 20:36.930] When we tore it apart over at the PLX cert, we discovered that for the most part it's primarily just get floods and post floods. [20:36.930 --> 20:42.030] It's, you know, they'll have several different named attacks. [20:42.310 --> 20:44.530] But when you look at the traffic, it's just a get flood. [20:44.810 --> 20:48.790] And it'll make use of... it'll try to randomize the HTTP headers, the refers. [20:50.390 --> 20:56.630] Yeah, mostly the refers and the user agents to try to avoid detection and make it look like legitimate traffic. [20:57.710 --> 21:00.670] But again, it always has static signatures. [21:00.910 --> 21:04.390] So we put together a very comprehensive analysis of it. [21:04.390 --> 21:14.670] You can... we have mitigation signatures available to the public as well at prolexic.com forward slash ddos-dirt-jumper.html. [21:15.090 --> 21:25.130] We do release periodic threat advisories that reverse engineer these toolkits and discuss what they do, how they work, and the best ways to mitigate them on your network. [21:25.290 --> 21:31.350] And it's available free to the public from prolexic.com from the threat advisory section. [21:34.210 --> 21:37.010] Here's an image of the Dirt Jumper control panel. [21:37.230 --> 21:39.450] It's against a very stripped down interface. [21:39.870 --> 21:42.470] It has one... it only has a couple inputs. [21:43.450 --> 21:49.590] The target, the URL, how many threads or flows do you want the machine to run against it. [21:49.950 --> 21:51.330] And then there's a start and stop button. [21:51.730 --> 21:53.730] This is a screenshot from version 3. [21:53.730 --> 21:59.430] When we did the analysis, that was the version that was publicly leaked. [21:59.650 --> 22:10.790] Since we've released the threat advisory, Dirt Jumper 5 has come out and advertises that it has an anti-DDoS mitigation feature that randomizes additional headers during a post-flood. [22:10.790 --> 22:24.070] It seemed to be more hype than actual... than an actual threat regarding being able to beat DDoS mitigation because all it did was add an extra randomization field on the post-flood and then called it an anti-DDoS flood. [22:24.350 --> 22:29.530] So it was mostly just... seems to be mostly just a marketing technique. [22:32.890 --> 22:37.030] And also... also that's come out within the last... [22:37.030 --> 22:40.570] gained prevalence within the last couple years has been booterscripts. [22:40.850 --> 22:50.390] These are used in denial of service attacks or DDoS attacks that they're simple stripped down PHP or ASP files. [22:50.510 --> 22:51.450] It's just a single file. [22:51.610 --> 22:52.410] They're freely available. [22:52.530 --> 22:56.190] You can go to Pastebin and type booterscript and you'll see dozens of examples of them. [22:57.170 --> 23:02.090] Essentially all they're doing is sending get floods or UDP floods. [23:02.490 --> 23:04.470] And they're incredibly simple to use. [23:05.430 --> 23:15.190] You can get... what a lot of novice attackers are doing is they'll obtain these public booterscripts from either a forum or Pastebin. [23:15.410 --> 23:21.290] Then they'll just sign up with a bunch of free hosts, put the file on the free host and then set it to start attacking a target. [23:21.770 --> 23:26.430] And eventually free hosts kind of catch on to that and set up signatures for these publicly known shells. [23:26.950 --> 23:27.890] Not all of them are doing it. [23:27.990 --> 23:30.290] So it can still be pretty effective for a short period of time. [23:30.890 --> 23:37.170] But through very simple web application vulnerabilities, attackers are also uploading these files to web servers. [23:37.690 --> 23:54.350] So basically what happens is through a simple remote file inclusion or any way to write a file to a server, an attacker is able to convert that server through a single file upload and turn it and use all the bandwidth from that server in a DDoS attack. [23:54.590 --> 24:02.610] Which is significantly more powerful than infecting a bunch of workstations with a piece of malware and having them work all together. [24:02.830 --> 24:07.970] So basically it's with less effort to spread these... [24:07.970 --> 24:14.390] Basically attackers are able to use less machines that are easier to infect to do more powerful attacks. [24:14.950 --> 24:17.990] And booterscripts are a big reason for this. [24:17.990 --> 24:22.830] I have some screenshots of what they actually look like and what their interfaces are. [24:24.370 --> 24:28.650] You can get these long lists of booter shells that just circulate on Pastebin. [24:29.210 --> 24:48.830] And there are programs called boot loaders, which are either standalone clients written by people who are usually just getting into programming or these web application-based boot loaders where you can just feed a list of these shells into the boot loader and give it the target and it will start hitting them all. [24:49.330 --> 25:01.010] And what's interesting about the communication methods of these is these traditional botnets like Dirt Jumper that are malware-based rely on the command and control server to... [25:01.010 --> 25:06.570] Well, actually they rely on the infected client to connect back to the command and control server and receive instructions. [25:06.810 --> 25:13.150] Whereas these sit quietly awaiting to receive instructions from the attacker or the boot loader. [25:13.150 --> 25:17.250] And the only way they'll receive those instructions is if you know where they're actually located. [25:17.910 --> 25:28.770] And there's an entire economy based around these where hackers will just go around infecting web servers, dropping booterscript shells and they'll sell the lists to people who want to be able to use DDoS attacks. [25:28.830 --> 25:31.470] Like, oh, you don't know how to do a web application attack. [25:31.690 --> 25:33.010] Here's a list for a few bucks. [25:33.110 --> 25:35.450] You could just use this list to start attacking these websites. [25:36.010 --> 25:48.610] And again, PLXCert has done a comprehensive analysis of several booterscripts, how they work, the economy that surrounds them, and the entire script kitty scene that surrounds it. [25:48.730 --> 26:00.190] But it's actually pretty sophisticated and pretty and way more powerful than it should be because of the amount of bandwidth that these scripts are able to utilize from compromised servers. [26:00.930 --> 26:04.330] And that's at prolexic.com forward slash threadadvisories.html. [26:06.410 --> 26:09.030] Here's a screenshot of the green shell booterscript. [26:09.610 --> 26:11.950] Very simple, straightforward PHP file. [26:12.050 --> 26:17.570] Once it's uploaded to the server, all it asks for is the destination and the length of time you want to run the attack for. [26:17.750 --> 26:20.230] And all this does is send a UDP flood. [26:20.230 --> 26:35.810] So if you don't want to have to even use this little GUI interface, you can just send a get request of, you know, green shell.php, question mark, target equals, and time equals. [26:36.210 --> 26:42.290] And then essentially what boot loaders do is it will just send those commands to the entire list of shells. [26:42.290 --> 26:59.070] And then you're able to leverage a pretty powerful DDoS attack using incredibly simple tools and techniques that really shouldn't work in 2012, but they are and they're gaining way more prevalence because they're easier to do, more people are using them, [26:59.150 --> 27:01.250] and this is the result. [27:01.630 --> 27:11.190] And what's another interesting thing about the green shell booterscript, it's not displaying here, but there's a broken image within the green shell booterscript that used to be a big pot leaf. [27:11.190 --> 27:17.430] And that was hosted on the server of one of the, I guess, I'm guessing one of the authors of the script. [27:17.690 --> 27:27.730] So what would happen is every person who would use this tool and drop a shell on a server, any time it would be accessed, the image would make a request to the server that's being hosted. [27:27.890 --> 27:32.530] So the guy who wrote the script is just getting all these nice long lists of infected machines. [27:33.390 --> 27:36.990] And that's fairly common with a lot of these scripts. [27:39.870 --> 27:43.330] And we talked a little bit about opt-in DDoS tools. [27:43.890 --> 27:45.550] This is the low orbit ion cannon. [27:46.150 --> 27:50.470] This is, it's got a lot of people arrested because it has no support for proxies whatsoever. [27:51.130 --> 27:55.030] And most people don't know how to use, a lot of people using it didn't know enough to use VPNs. [27:56.370 --> 28:01.470] It's simply, it's just a very simple get flood, very stripped down headers, nothing that fancy. [28:01.790 --> 28:05.810] It crashes a lot, especially when you want to use a high thread count. [28:05.930 --> 28:14.770] It only becomes effective when you have large amounts of people coordinating to users in an attack, like with the anonymous campaigns. [28:14.770 --> 28:25.130] And what was something that was real funny is during those campaigns when this was circulating among those groups on IRC, a lot of people were backdooring them with Zeus because why not? [28:25.530 --> 28:29.330] And everyone who was participating in the attack became part of a larger botnet. [28:32.030 --> 28:34.090] This is the high orbit ion cannon. [28:34.610 --> 28:38.470] Very similar to low orbit ion cannon, it was just the next generation of it. [28:38.470 --> 28:51.610] This makes use of booster scripts, which are these visual VBScript files that you're able to feed into the tool that are basically lists of randomized headers and randomized headers like referrers and user agents. [28:52.170 --> 28:57.810] And that has the attempt to bypass any type of mitigation or detection. [28:58.130 --> 29:00.770] But again, it crashes a lot. [29:00.930 --> 29:02.110] It's pretty poorly coded. [29:03.130 --> 29:08.410] It has no support for proxies and is only effective when you're using it with a large group of people. [29:08.410 --> 29:09.110] and coordinating. [29:09.370 --> 29:15.470] And we've also done a comprehensive analysis of this tool and reversed it. [29:15.650 --> 29:17.890] And that's available on the Prolexic Threat Advisory section. [29:20.550 --> 29:24.090] Recently in the news, Xemra has been getting a bit of press. [29:25.050 --> 29:41.170] It got a lot of hype because it seemingly combined the features of Zeus and SpyEye with DDoS capabilities, which was fairly innovative, hadn't really been seen to be that popular of a combination. [29:41.810 --> 29:49.150] It's based off the seek malware kit, almost identical in database structure and user and command and control user interface. [29:49.950 --> 30:00.990] They make some pretty impressive claims about the tool in the advertisements on underground forums, to the point where it's a bit suspicious as to if this is actually a functional tool. [30:01.350 --> 30:03.330] For example, it's only selling for $100. [30:03.890 --> 30:13.750] And compared to the market price of other tools, that is way too cheap for something that supposedly has these features and also has the ability to spread via USB infection. [30:14.850 --> 30:20.850] Just that alone flagged something that there's not something legit about this crimeware product. [30:22.330 --> 30:28.270] And the tool was released for private sale, I'd say about April or May. [30:28.790 --> 30:31.930] And within a few weeks, it was already leaked. [30:32.090 --> 30:35.510] And the code was... the builder code and the CNC panel code was available. [30:35.890 --> 30:45.230] So that... and when you go through the code, it shows that a lot of the code seemed to have been ripped ripped from things like the seek malware kit, but it could have been the same author. [30:45.410 --> 30:47.650] But the builder was also ripped from some other... [30:47.650 --> 30:52.550] portions of it ripped from some other popular German botnets as well. [30:52.750 --> 30:58.610] So that's pretty common among inexperienced malware coders to just borrow code from other projects. [30:59.130 --> 31:09.150] And since there was no copy protection, licensing or any of the fancy things that now exist in crimeware kits, it shows that they're somewhat inexperienced. [31:09.150 --> 31:11.850] And that's another thing that developed within the last two years. [31:12.650 --> 31:14.610] Licensing for... for crimeware kits. [31:15.150 --> 31:19.790] Which... to the point where it's, you know, it's the... the PHP scripts will be encoded. [31:19.890 --> 31:20.710] You can't even see them. [31:20.850 --> 31:26.450] It's just, you know, it's... it's... it's built... encoded to your server and only work with your server. [31:26.650 --> 31:31.090] And they'll have these managed update services that'll just push out the updates to when it's ready. [31:31.350 --> 31:34.750] And they'll be based in countries where there's absolutely nothing that can be done about that. [31:35.650 --> 31:47.810] And, um... another interesting thing about the... the Xemera leak, which is common to most other leaked products, they're all backdoored by default with the most obvious backdoor of... that's... I've... I've ever seen. [31:48.250 --> 31:55.570] Um... if you just go to systemcommand.php, it's a PHP CMD command. [31:55.570 --> 32:01.510] You can just question mark CMD equals cat /etc/password or any command and that's it. [32:01.650 --> 32:02.570] You've... you've got it. [32:02.830 --> 32:06.970] And mostly what people are using is to dump configuration files and they can get login creds. [32:07.110 --> 32:09.490] And then they can take over the... take over the botnet. [32:09.950 --> 32:18.850] So... basically... and what I'm... what I assume is that the person who leaked this toolkit, um... was just looking to take over other command and control panels. [32:18.850 --> 32:22.270] And, um... noble calls, it seems to be work. [32:22.350 --> 32:24.050] Got a bunch of... got a bunch of press. [32:24.290 --> 32:26.550] So I'm... I'm sure they're... I'm sure they're doing that. [32:27.070 --> 32:32.590] And, um... that was just, uh... one that we're able to see just by looking at the files. [32:32.590 --> 32:34.230] Like, command.p, what's this? [32:34.350 --> 32:34.530] Oh. [32:34.970 --> 32:37.570] So, like, I'm sure there's... I'm sure there's SQL injections. [32:37.770 --> 32:41.630] I'm sure there's all sorts of, you know, horrible vulnerabilities within this... within this panel. [32:41.990 --> 32:42.790] It's... it's free. [32:42.890 --> 32:43.810] Just Google for Xemera. [32:43.810 --> 32:47.090] Um... you'll be able to download it and... how many can... can you find? [32:47.270 --> 32:49.350] You know, it's, uh... it's probably... probably several. [32:51.590 --> 32:53.790] And, um... just a... a brief note about cryptocurrency. [32:54.790 --> 32:57.390] Um... in January 2011, Bitcoin was born. [32:57.630 --> 33:04.370] And within the last two years, it's gone from... up to... as high as $31 to as low as, you know, almost less than a penny. [33:05.170 --> 33:11.090] Um... and... but... within the last six months, for whatever reason, it's remained stable, uh... between $4 to $7. [33:12.750 --> 33:16.550] Um... in addition to Bitcoin, there's other cryptocurrencies that have emerged to compete with it. [33:16.730 --> 33:17.650] Things like SolidCoin. [33:18.210 --> 33:20.750] Um... it's... SolidCoin is definitely not worth as much. [33:20.950 --> 33:22.830] Probably... they're probably only worth a few cents a coin. [33:23.010 --> 33:29.570] But it's the same principles, same, uh... you know, same algorithms, the same distributed peer-to-peer, uh... network type deal. [33:30.210 --> 33:34.010] And, um... it's... it's all... the prices are based on supply and demand. [33:34.350 --> 33:47.390] And, um... when... when Bitcoin came out, you had all the... you had a few darknet sites who would do things like sell drugs or sell, you know, other illegal transactions are very possible with Bitcoin because it's, um... because it's just like cash. [33:47.550 --> 33:48.930] There's... there's no central authority. [33:49.450 --> 33:53.510] People can send, uh... a physical encrypted file from one person to another. [33:53.830 --> 33:59.430] And the... the value of that file is just agreed upon by the... by the buyers in the marketplace in general. [33:59.570 --> 34:02.510] Just like, you know, worthless Federal Reserve fiat currency or whatever. [34:02.510 --> 34:06.430] It's just... you know, it's trusted by the users and the supply and demand sets the market rate. [34:07.590 --> 34:11.650] Um... it's, uh... how... the... you know, Schumer from, uh... [34:11.650 --> 34:18.410] the... the Senate made a big deal about it when it got into the news about, you know, the... oh, the... the Silk Road drug marketplace that takes Bitcoin. [34:18.790 --> 34:22.070] But that... it's... that's really kind of an anomaly. [34:22.350 --> 34:29.230] Uh... for the most part, Bitcoin hasn't really made, uh... been, uh... a big player within the underground economy. [34:29.230 --> 34:30.930] You'll see it every now and then. [34:31.070 --> 34:32.730] A few people will... will accept it. [34:32.850 --> 34:35.770] But it's mostly just because they're kind of curious in the concept of cryptocurrency. [34:36.250 --> 34:39.570] But it's... it's not, um... really an accepted form. [34:39.790 --> 34:42.650] And I... I believe that to be because of the market fluctuations. [34:43.310 --> 34:49.050] Um... the... the malicious actors are still making use of Liberty Reserve or Yandex money, which is another fairly new one. [34:49.610 --> 34:53.250] Um... which is matched, uh... which is matched, you know, one-to-one to the U.S. [34:53.370 --> 34:55.990] dollar or whatever currency it is in the... the country they're using. [34:56.390 --> 34:57.190] Uh... the country that they're in. [34:57.190 --> 35:04.730] Um... the... the market fluctuations of Bitcoin, uh... make it pretty, uh... unattractive for... for long-term cybercrime operations. [35:05.110 --> 35:11.830] Because they... because of the, you know, the... the crazy fluctuation, you know, $31 to less than a... than... less than a penny. [35:12.410 --> 35:18.470] Um... people who are engaged in... in, uh... you know, digital crime for their... for a living. [35:18.770 --> 35:21.550] Um... they can't... they don't... they don't want to place that gamble on it yet. [35:21.550 --> 35:39.050] So, it's, um... again, while there's a few, uh... malicious actors that, uh... do take Bitcoin, and there's even been, uh... botnets based off Bitcoin, where, um... if a... if you get infected, your machine just starts mining Bitcoin, and then will send the... the coin that it mines to a destination wallet. [35:39.430 --> 35:47.950] And those... the... there are several kits like that that are circulating, and, um... I... I haven't, uh... reversed any of them, but they... they seem to be fairly interesting. [35:48.670 --> 35:56.770] Um... but, uh... aside from those few little curious anomalies, it... it hasn't really, uh... gained a foothold as a currency of choice within the underground. [35:56.970 --> 36:01.790] And that's probably a good thing, because Bitcoin can be used to do a whole... you know, a whole bunch of legitimate cool things. [36:01.930 --> 36:03.070] So, you could buy hosting with it. [36:03.210 --> 36:05.970] You could buy... you know, I've even bought beef jerky with it. [36:06.050 --> 36:07.150] It's... it's really cool. [36:07.650 --> 36:10.870] Um... there's... and, um... as long as, uh... you know, there's... [36:10.870 --> 36:16.930] as long as the mainstream media and government isn't focusing on the... the... the things that can be done... [36:16.930 --> 36:20.970] bad... the bad things that can be done with it, um... there's a potential for a lot of good to be done with it. [36:21.190 --> 36:23.910] But... my... my impression is that Bitcoin is seen as a... [36:23.910 --> 36:28.010] as a... as an actual threat to, um... to the... to the current, um... [36:28.010 --> 36:35.650] financial system that's in place because it's a decentralized peer-to-peer digital currency that is actually worth more than the U.S. dollar right now. [36:38.530 --> 36:40.450] So, what's to come in the future? [36:40.450 --> 36:42.370] What's... you know, where... what's next? [36:43.030 --> 36:44.550] Um... most likely we're gonna... [36:44.550 --> 36:47.070] I... I predict we're gonna see an increase in mobile device malware. [36:47.330 --> 36:49.930] As more and more people start using their phones, um... [36:49.930 --> 36:58.050] to... to do bank transactions, email, and just kind of centralizing all their logins onto their phone, especially as multi-factor authentication makes use of cell phones. [36:58.970 --> 37:04.670] Um... mobile device malware is gonna be an integral part of cybercrime toolkits because they're gonna be needed to... [37:05.090 --> 37:11.150] you're gonna need to infect phones in order to extract the multi-factor authentication credentials, which are gonna be needed for a lot of web applications. [37:11.410 --> 37:13.790] And that's... that's already starting to... to come out. [37:14.590 --> 37:19.650] Um... as... and, uh... as HTML5 becomes more popular, there's gonna be more client-side attack vectors. [37:20.130 --> 37:23.530] Um... there's gonna be, uh... more browser vulnerabilities that are gonna be leveraged. [37:23.730 --> 37:25.730] Um... client-side SQL injections, uh... [37:25.730 --> 37:35.250] gonna become more and more common on both mobile devices and desktop PCs because HTML5 allows the creation of client-side SQL injection... uh... client-side SQL databases. [37:36.030 --> 37:41.050] And there's gonna be new XSS attacks variants that are gonna be... that are gonna be, uh... [37:41.050 --> 37:49.510] available, um... because HTML5 is using, uh... because HTML5, um... allows for new types of commands and functions. [37:50.710 --> 38:02.810] And, uh... as far as DDoS attacks go, um... as more and more of these toolkits are being released, as it becomes easier and easier to launch significant attacks using... using, uh... large amounts of bandwidth. [38:03.510 --> 38:09.990] Um... it's going... it's going to be... continue to... to grow and, um... and become, uh... become an issue. [38:12.490 --> 38:21.270] And... and, uh... again, here's some... some resources for, uh... for, um... anyone who... who would like more information on any of the stuff that was discussed today. [38:21.790 --> 38:26.370] Um... the... all the... the DDoS, um... tools that were discussed, um... [38:26.370 --> 38:29.550] are available from the threat advisory section at prolexic.com. [38:29.810 --> 38:31.170] Uh... it's free... free to the public. [38:31.490 --> 38:33.370] Just, uh... go ahead and... and download it. [38:33.910 --> 38:39.130] Um... uh... the collective intelligence framework is a really, really neat, uh... project that's... [38:39.130 --> 38:50.190] recently been developed where it'll take, uh... the feeds from all the different malware tracking, um... malware tracking sites like, uh... Zeus Tracker, uh... CleanMx, uh... Spy Eye Tracker. [38:50.430 --> 38:52.070] If... if you can name it, it's already on the list. [38:52.070 --> 39:00.310] And then it centralizes it all so that you're not having to, uh... you know, basically bounce through all these different resources to... to pull, um... command and control centers. [39:00.790 --> 39:07.490] It's just, uh... collective intelligence framework will just centralize it all and pull all sorts of, uh... statistics and data through it. [39:07.990 --> 39:17.330] Um... also, uh... regarding, uh... one of the prolexic threat advisories and the Dirt Jumper threat advisory, uh... we have a tool that we released called, uh... Dirt Dozer dot, uh... PY. [39:17.330 --> 39:22.130] and you can feed a list of command and control servers to, uh... to the Python script. [39:22.330 --> 39:24.690] It will fingerprint them if they're... if they're Dirt Jumper. [39:24.950 --> 39:27.770] Tell you the type of attack and the target of the attack. [39:28.030 --> 39:33.790] So if you have a list of command and control servers, you can identify who's being hit, uh... with Dirt Jumper and how. [39:34.630 --> 39:40.590] And, um... some good open-source intelligence resources just to... for good feeling of what's... what's going on in the underground. [39:40.590 --> 39:44.290] Uh... OpenSC dot WS is, uh... is a malware forum. [39:44.510 --> 39:48.230] Um... it's up and down all the time because it's, uh... it's a malware forum. [39:48.890 --> 39:52.110] And, um... it's... but a lot of good leaks end up... [39:52.110 --> 39:55.550] a lot of good leaks end up showing up there before they show up anywhere else. [39:56.550 --> 39:58.210] Uh... Krebs on security dot com. [39:58.670 --> 40:00.850] Uh... it's, uh... Brian Krebs, an investigative journalist. [40:01.050 --> 40:07.410] Uh... he's always putting out real good information about, um... about, uh... developments in the... in the digital underground. [40:07.970 --> 40:16.570] Uh... cyberwarnews.info is a good gossip page for, you know, hacker, you know, group rival battles and stuff and who's defacing who and who's doxing who. [40:17.310 --> 40:22.090] And, um... zoneh.org, um... real cool archive of defaced websites. [40:22.410 --> 40:31.630] Um... there's all these different defacement crews that are just... any time that they'll hit, like, a bulk list of domains to deface them all, they'll all try to get, you know, rep points by posting up on zoneh.org. [40:32.190 --> 40:35.530] And, um... payspin.com for pretty much everything else. [40:35.530 --> 40:38.830] Just search for the keywords and you will... you will find stuff. [40:41.870 --> 40:42.630] And... thank you. [40:42.910 --> 40:46.490] If, uh... I guess, um... anyone wants to contact me, uh... alex at hackmiami.info. [40:47.110 --> 40:52.570] Um... you know, uh... we got all the crimeware kits downstairs, uh... for anyone who wants to try out any of the vulnerabilities. [40:53.350 --> 40:56.110] And, um... that's at the Hack Miami table. [40:56.230 --> 40:58.810] You'll see a big percent 27 on the table in the mezzanine level. [40:59.050 --> 41:01.210] And if there's any questions, I'll take questions. [41:11.230 --> 41:11.730] There you go. [41:12.430 --> 41:12.590] All right. [41:12.910 --> 41:12.970] Cool. [41:13.410 --> 41:13.950] Thank you very much. [41:14.730 --> 41:15.770] Oh, there's a question in the back. [41:38.500 --> 41:39.080] Uh... I'm sorry. [41:39.400 --> 41:40.740] Uh... I... I didn't hear the full question. [41:40.840 --> 41:42.420] What's the overall situation with... [41:50.340 --> 41:53.700] Uh... through... you're saying delivering, uh... malware through peer-to-peer networks? [42:17.090 --> 42:17.570] Yeah. [42:17.570 --> 42:18.170] Um... yeah. [42:18.430 --> 42:23.370] I... I... I wasn't able to... to... to fully, uh... hear everything, because it's, uh... it's pretty noisy. [42:23.570 --> 42:28.930] But, um... there... there are all sorts of, um... vectors of exploitation which are being leveraged for these... for these types of toolkits. [42:29.290 --> 42:33.110] Um... uh... pretty much if... if... if you can envision it, it's... it's... it's being done. [42:34.230 --> 42:36.630] I took this from taking and getting... [42:36.630 --> 42:36.670] Oh, hey. [42:36.670 --> 42:36.870] Awesome. [42:37.070 --> 42:37.170] Cool. [42:37.430 --> 42:37.430] Thanks. [42:37.810 --> 42:38.190] Yeah. [42:40.590 --> 42:40.690] Yeah. [42:46.700 --> 42:47.260] Yeah. [42:47.260 --> 42:47.540] Yeah. [43:05.510 --> 43:12.290] Well, the... the bootloaders are usually, um... they're... they're... they're usually just a... a single executable application that... [43:12.290 --> 43:13.330] Yeah, exactly. [43:13.550 --> 43:22.450] There's, like... some of the real fancy ones, they'll do, like, a PHP, MySQL thing, and they'll sell services so that people can pay a fee to log in to the bootloader and then run their own lists. [43:22.790 --> 43:27.270] But for, um... for the most part, the... the attacker needs to already have a list. [43:27.950 --> 43:34.490] Yeah, you just... yeah, you just need to know the URL of where the bootloader's at, and then you can send it, uh... target and time limits, and it'll start hitting it. [43:48.040 --> 43:55.200] Um... well, there... there's still, um... um... uh... exploits being delivered through... through advertisements like Flash vulnerabilities. [43:55.720 --> 44:00.380] Um... it's just not as prevalent anymore, because Adobe's done a pretty good job over the last two years of... of fixing that. [44:00.560 --> 44:09.240] But there are still zero days to get discovered in... in Flash, and that, uh... um... infections through, uh... through dirty advertisements is still a very common thing. [44:10.200 --> 44:22.280] And, um... and, um... also regarding, if you're talking about adware, like, the advertisements that infect a machine, and you start giving you the pop-ups and stuff, um... those... those are usually already existing, and they use that to push out another executable. [44:22.500 --> 44:29.460] More, like, like, from, um, like... normally, we should be a topic that isn't, like, a drug or something like that, but, like, it is, you [44:35.530 --> 44:36.590] know... [44:38.350 --> 44:38.710] Um... [44:38.710 --> 44:38.910] Um... [44:41.810 --> 44:45.290] Well, uh... in a... in a... in a target, or there's... well, basically, the way that... [44:45.290 --> 44:47.310] the exploit kits work is they'll... they'll fingerprint the attack. [44:47.470 --> 44:49.730] They'll... they'll hit everything, and they'll just see what's vulnerable. [44:50.210 --> 44:53.970] And Java is usually the last resort, because most people run Java. [44:54.190 --> 44:56.050] So, it'll try to do a browser exploit. [44:56.170 --> 44:57.550] If that doesn't work, it'll try to do a Flash exploit. [44:57.650 --> 45:00.870] If that doesn't work, if that... then it'll... then it'll try to load up a Java applet. [45:01.310 --> 45:05.570] And, um... an interesting example of a target attack is, um... uh... the Brian Krebs blog. [45:06.030 --> 45:17.750] Um... he would... he, uh... he would go on to certain, uh... underground forums, and once they discovered that it was an investigative journalist, They decided to buy ad space on his website that was maliciously coded. [45:18.270 --> 45:20.630] And he had to approve it, so he caught it. [45:20.810 --> 45:23.990] But if it had gone all the way through, it would have started infecting people. [45:31.270 --> 45:37.570] Yeah, it's very possible to embed iframes and dirty JavaScript into advertisements that are purchased. [45:37.770 --> 45:40.390] And that's still a very common infection method for drive-by downloads. [45:44.050 --> 45:45.510] Yeah, in terms of [45:48.620 --> 46:04.320] a platform or a library thing, instead of just using server resources or using a botnet, and actually just posts and links, and either through an ad, or if you could just hit a popular website, stick with [46:10.400 --> 46:14.720] something distributed to the legitimate users, it wouldn't be obvious. [46:15.220 --> 46:17.200] Yeah, that does exist. [46:17.460 --> 46:31.940] There has been JavaScript versions, versions of the low orbit ion cannon and other similar DDoS tools, where people can just start sticking iframes on infected sites, and basically just by hitting that website, the JavaScript will start making the visitors start sending get requests. [46:32.120 --> 46:34.980] So basically you're able to distribute all those attacks against a legitimate user base. [46:35.140 --> 46:37.700] So as long as the website's open, attacks are being run. [46:37.880 --> 46:44.380] So that definitely exists, and that's another stepping stone of where things are probably going to be going more into the future. [46:44.380 --> 46:46.640] or basically DDoS without infection. [46:48.040 --> 46:49.240] Any other questions? [46:50.620 --> 46:51.400] Oh, cool. [47:08.420 --> 47:26.960] I believe, again this is my hypothesis, I don't have any proof of this, but I believe a lot of the mobile applications and enumerations of the existing crime records, like MobileJuice, I believe it's probably developed by third parties who are obtaining the leaked code and then just making changes to it. [47:27.080 --> 47:37.260] But I'm pretty sure some of the original authors might still be involved with that, but there's also been rumor and chatter within the underground that the authors have retired and that type of stuff. [47:37.480 --> 47:41.540] So really, who knows, it's all a bunch of handles and all the handles could be the same person. [47:44.440 --> 47:45.520] Any more questions? [47:47.740 --> 47:48.660] All right. [47:49.040 --> 47:51.420] Well, thank you all for coming out. [47:57.250 --> 47:59.130] Guys, my name is Val. [47:59.390 --> 48:04.830] If anyone came here, not just to listen to the lecture, but maybe make another acquaintance. [48:05.330 --> 48:10.790] You know, I'm Russian, obviously my English is not perfect, but I'm available, so you can just come to me.